CVE-2022-20796

MEDIUM

ClamAV <0.104.2 - DoS

Title source: llm
STIX 2.1

Description

On May 4, 2022, the following vulnerability in the ClamAV scanning library versions 0.103.5 and earlier and 0.104.2 and earlier was disclosed: A vulnerability in Clam AntiVirus (ClamAV) versions 0.103.4, 0.103.5, 0.104.1, and 0.104.2 could allow an authenticated, local attacker to cause a denial of service condition on an affected device. For a description of this vulnerability, see the ClamAV blog.

Scores

CVSS v3 6.5
EPSS 0.0003
EPSS Percentile 9.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-476 CWE-822
Status published
Products (11)
cisco/secure_endpoint < 1.16.3
cisco/secure_endpoint < 1.17.2
cisco/secure_endpoint < 7.5.5
clamav/clamav 0.103.4
clamav/clamav 0.103.5
clamav/clamav 0.104.1
clamav/clamav 0.104.2
debian/debian_linux 9.0
fedoraproject/fedora 34
fedoraproject/fedora 35
... and 1 more
Published May 04, 2022
Tracked Since Feb 18, 2026